Purpose and Scope
This policy covers information assets, information systems, employees, suppliers, business partners and related processes used in company activities.
Core Principles
- Ensuring that information is accessible only to authorised persons.
- Protecting the accuracy and integrity of information.
- Ensuring that information and systems are available when required.
- Assigning access rights according to duties and business needs.
Risk Management
Information security risks are evaluated regularly. Appropriate technical, administrative and physical controls are implemented to reduce identified risks.
Legal and Contractual Compliance
Information security activities are carried out in accordance with applicable legislation, contracts, internal policies and relevant standards.
Employee and Supplier Responsibilities
Employees, suppliers and other parties with access to information systems are required to comply with the information security rules communicated to them.
Incident Management
Information security incidents are recorded and assessed, and necessary corrective or preventive actions are implemented.
Continuity and Improvement
The effectiveness of information security controls is reviewed regularly. Continuous improvement of business continuity and information security systems is targeted.
Management Commitment
Senior management is committed to providing the resources required to achieve information security objectives, implementing controls and continuously improving the system.